Instructions to use jeikei97/modelscan-keras-compile-config-lambda-bypass with libraries, inference providers, notebooks, and local apps. Follow these links to get started.
- Libraries
- Keras
How to use jeikei97/modelscan-keras-compile-config-lambda-bypass with Keras:
# Available backend options are: "jax", "torch", "tensorflow". import os os.environ["KERAS_BACKEND"] = "jax" import keras model = keras.saving.load_model("hf://jeikei97/modelscan-keras-compile-config-lambda-bypass") - Notebooks
- Google Colab
- Kaggle
YAML Metadata Warning:empty or missing yaml metadata in repo card
Check out the documentation for more information.
modelscan-keras-compile-config-lambda-bypass
This repository contains a proof of concept for a scanner bypass in .keras model files.
Vulnerability
The open-source protectai/modelscan Keras logic only inspects serialized model layers.
That misses a second deserialization surface that Keras also loads from .keras archives:
compile_config
A malicious .keras file can hide a serialized dangerous __lambda__ inside the compiled loss configuration while keeping the model layers completely benign.
Keras still treats the lambda as unsafe and rejects it in safe_mode=True, but modelscan returns no findings because it never inspects compile_config.
Primary PoC
The main PoC file is:
artifacts/compile_lambda.keras
The payload is harmless. When the model is loaded unsafely and evaluated, it writes a local marker file at:
KERAS_COMPILE_MARKER.txt
Included Files
artifacts/compile_lambda.kerasartifacts/reproduce_output.txtartifacts/sha256sums.txtreproduce.py
Tested Environment
- Date tested: July 17, 2026
- Python: 3.13.12
- Keras: 3.15.0
- Backend: NumPy (
KERAS_BACKEND=numpy) modelscan:protectai/modelscan@61fcec9c2a37c24c1fb12d84ede30fe248a364bd
Reproduction
1. Verify the included PoC
Run:
KERAS_BACKEND=numpy python reproduce.py --modelscan-path /path/to/modelscan
If modelscan is already installed in your environment, --modelscan-path is optional.
Expected results:
- top-level layer classes are
InputLayerandDense - the compile loss is serialized as
__lambda__ safe_mode=Truerejects the model as unsafesafe_mode=Falseloads the modelmodel.evaluate(...)creates the marker filemodelscanhelper returns[]modelscanhelper scan path reports zero issues and zero errors
2. Rebuild the artifact from source logic
Run:
KERAS_BACKEND=numpy python reproduce.py --build --modelscan-path /path/to/modelscan
This regenerates artifacts/compile_lambda.keras and reruns the verification steps.
Observed Results
From artifacts/reproduce_output.txt:
top_level_layer_classes: ['InputLayer', 'Dense']compile_loss_class: __lambda__safe_mode=Truerejects the modelsafe_mode=Falseloads successfully- marker file is created during evaluation
modelscan_helper_operators: []modelscan_helper_issue_count: 0modelscan_helper_errors: 0
Impact
This is a practical scanner bypass for a supported format:
- the file is a valid
.kerasmodel - the malicious operator is still a real serialized lambda
- Keras still treats it as unsafe
- existing scanner logic misses it because it only checks the layer graph
Notes
- The included artifact is intentionally harmless and only writes a marker file.
- This is a different primitive from a nested
Lambdalayer bypass: the model layers are benign and the payload is hidden incompile_config.
- Downloads last month
- 20